Impact
An unauthenticated attacker who can reach the Oracle Coherence service over HTTP can retrieve a subset of data stored in the Coherence cluster. The flaw resides in the Core component and permits read access without requiring any credentials. This is an Information Exposure flaw (CWE-200) that results in a partial confidentiality loss; integrity and availability are unaffected.
Affected Systems
The vulnerable versions include Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. These are part of Oracle Fusion Middleware and are distributed by Oracle Corporation.
Risk and Exploitability
The CVSS base score is 5.3, with the vector indicating network exploitation, low complexity, no user interaction, and a low confidentiality impact. The EPSS score is reported as less than 1%, suggesting a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. This is an Information Exposure weakness (CWE-200) that can be exploited by sending constructed HTTP requests to the Coherence service, obtaining data without authentication. Therefore, the risk is moderate but can be mitigated by applying an available patch or remediation.
OpenCVE Enrichment